Critical infrastructure
Initial situation
The term “critical infrastructure” or
“strategic infrastructure” describes those
parts of all public or private infrastructures
that are of crucial importance for
maintaining vital societal functions. Their
disruption or destruction has a major
impact on the health, security or economic
and social wellbeing of the citizens or the
effective functioning of state institutions.
Today most critical infrastructures
increasingly depend on specialised IT
systems which are expected to guarantee
services as smoothly, reliably and
continuously as possible. The ICT sector
itself (and its IT and telecommunications
networks with their various components
and providers) as well as the ICT-based
infrastructures of all other sectors not
only permit sectoral production, but also
keep the trans-sectoral flow of information
going. In more general terms, these are
also referred to as critical information
infrastructures (CII). The protection of
critical information infrastructure (CIIP)
is therefore not just a task for the ICT
sector alone, but has increasingly become a
concern of other economic sectors.
One particular characteristic of critical
information structures is their susceptibility
to different types of cyber attacks. This is
reflected in the fact that CIIs themselves
can be actively abused as “attack channels”
against other critical infrastructures. Unlike
failures of electricity or water supply, cyber
attacks may cause lasting—“sustainable”—
damage, e.g. through the targeted
destruction or manipulation of machine
control data.
In Austria cyber security goals
pursued to protect critical information
infrastructures must be coordinated with
the proven Austrian Programme for Critical
Infrastructure Protection (APCIP). An
overarching objective therefore correlates
with this programme as follows:
“The APCIP programme must be
complemented by cyber security measures
within and between the sectors; national
14
capacities to support information security
and cope with national crisis and disaster
situations have to be built up.”
Strategic objectives and measures
Objective 1: Cyber crisis management
Hypothesis: Cyber crises and disaster
situations may have fatal effects on the
state, the economy and public life. At
international level it has become an
established practice to build up special
overarching structures for events of
this kind to complement existing crisis
management structures.
Strategic objectives:
To further develop reactive tools for
a country-wide disaster and crisis
management relevant to cyber security
(cyber crisis management) to protect the
state, economy and public life from harm.
National cyber crisis management is an
important element of national security.
Measures
Establishing a structure for national
cyber crisis management: The factors
distinguishing national cyber security
management (“cyber crisis management”)
from conventional public disaster and
crisis management are, on the one hand,
the special requirements and overlapping
areas of cyber security, and on the other
constant cooperation with programmes
protecting critical infrastructures.
Another difference between cyber crisis
management and conventional public
disaster and crisis management is the
degree of networking required at national
and international level. Cyber crises at a
domestic level may be coped with only
with the aid of governmental (public) and
non-governmental (private) stakeholders
and depend on international cooperation in
almost all cases.